Fraud prevention method, fraud prevention device, and program
The fraud prevention method for FlexRay networks dynamically adjusts frame transmission timing based on fraud detection criteria, enhancing security by preventing unauthorized access and maintaining network integrity.
Patent Information
- Application Number
- JP2023173115
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2018-07-27
- Filing Date
- 2023-10-04
- Publication Date
- 2025-08-14
- Estimated Expiration
- 2039-07-23
AI Technical Summary
Existing fraud detection methods for in-vehicle networks, such as those using the CAN protocol, are not applicable to FlexRay networks, which use the TDMA method and predetermined communication intervals, and there is a need to enhance security measures to prevent unauthorized frame transmission.
A fraud prevention method and device that dynamically changes the transmission timing of frames in response to detected fraud, using specified information such as detection frequency, risk level, vehicle state, and communication policy, to prevent unauthorized access and maintain network security.
The method and device effectively maintain a safe in-vehicle network system by detecting and mitigating fraudulent frames, making it difficult for attackers to predict transmission timing and ensuring secure communication.
Smart Images

Figure 0007723712000001 
Figure 0007723712000002 
Figure 0007723712000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a fraud prevention method and a fraud prevention device on an in-vehicle network. [Background technology]
[0002] In recent years, automobile systems have been equipped with numerous devices called electronic control units (hereinafter referred to as ECUs). The network that connects these ECUs is called an in-vehicle network. There are many standards for in-vehicle networks. Among these is a standard called FlexRay (registered trademark), which was designed as a faster and more reliable protocol than the currently mainstream Controller Area Network (hereinafter referred to as CAN (registered trademark)).
[0003] In FlexRay, the voltage difference between two twisted wires represents the values "0" and "1." The ECUs connected to the bus are called nodes. Each node connected to the bus sends and receives messages called frames. FlexRay uses the Time Division Multiple Access (TDMA) method, and each node sends frames at a predetermined timing.
[0004] In FlexRay, there is a cycle, which is the largest unit of time, and each node synchronizes with the global time. A cycle consists of four segments: a static segment, a dynamic segment, a symbol window, and a network idle time, and the dynamic segment and symbol window are optional. Each node transmits frames in the static and dynamic segments. The static and dynamic segments are further composed of a time during which one frame can be transmitted, called a slot.
[0005] In FlexRay, there are no identifiers that indicate the destination or source, and the transmitting node transmits frames based on a slot number, which is a transmission timing that is predetermined for each frame. Each receiving node only receives frames with a predetermined slot number. In addition, a method called "cycle multiplexing" is sometimes used, which allows different frames to be communicated depending on the cycle, even for frames with the same slot number.
[0006] In addition, with FlexRay, it is possible to design not only a bus network topology in which all nodes are connected to a single bus like CAN, but also a star network topology via a star coupler, and a hybrid network topology that combines bus and star types.
[0007] On the other hand, with regard to security, there is a threat that an attacker could access the CAN bus and send malicious frames, thereby gaining unauthorized control of the ECU, and security measures are currently being considered.
[0008] For example, Patent Document 1 proposes an in-vehicle network monitoring device that detects whether frames are being transmitted to the CAN at a predetermined communication interval, and discloses a method for preventing control by unauthorized frames by determining that frames that deviate from the specified communication interval are unauthorized. [Prior art documents] [Patent documents]
[0009] [Patent Document 1] Patent No. 5664799 Summary of the Invention [Problem to be solved by the invention]
[0010] However, the fraud detection method described in Patent Document 1 cannot be applied to FlexRay, which uses the TDMA method and performs communication at predetermined communication intervals. It is also desirable to improve security in CAN.
[0011] Therefore, in order to solve the above problem, the present disclosure aims to provide a fraud prevention method and a fraud prevention device that can realize a safe in-vehicle network system by reducing the scope of impact caused by fraudulently transmitted frames. [Means for solving the problem]
[0012] In order to achieve the above object, a fraud prevention method according to one aspect of the present disclosure is a fraud prevention method in an in-vehicle network, comprising: message Send and receive stomach , unauthorized Message detection Do ,before For detection If fraud is detected in message Transmission timing of switching Do , the switching Ede changes the transmission timing of the destination according to the specified information The predetermined information includes at least one of the number of detections in the detection, information indicating the transmission time of the message in which the fraud was detected, the risk level of the message in which the fraud was detected, the vehicle state of the vehicle, the fact that an error in accordance with a communication policy was detected in the detection, and the fact that a message other than the message in which the fraud was detected was detected. .
[0013] Furthermore, a fraud prevention device according to one aspect of the present disclosure is a fraud prevention device in an in-vehicle network, message Send and receive message Transmitting and receiving parts and unauthorized message and when fraud is detected by the fraud detection unit, message and a switching processing unit that switches the transmission timing of ... The predetermined information includes at least one of the number of times the fraud detection unit has detected the fraud, information indicating the time of transmission of the message in which the fraud has been detected, the risk level of the message in which the fraud has been detected, the vehicle state of the vehicle, the fact that the fraud detection unit has detected the occurrence of an error in accordance with a communication policy, and the fact that the fraud detection unit has detected a message other than the message in which the fraud has been detected. . Furthermore, a program according to one aspect of the present disclosure is a program for causing a computer to execute the fraud handling method described above. [Effects of the Invention]
[0014] According to the fraud prevention method and the like according to one aspect of the present disclosure, a safe in-vehicle network system can be realized. [Brief explanation of the drawings]
[0015] [Figure 1] FIG. 1 is a diagram showing the overall configuration of an in-vehicle network system according to the first embodiment. [Figure 2] FIG. 2 is a diagram showing a cycle of FlexRay communication in the first embodiment. [Figure 3] FIG. 3 is a diagram showing a frame format of FlexRay communication in the first embodiment. [Figure 4] FIG. 4 is a diagram illustrating an example of the configuration of the ECU according to the first embodiment. [Figure 5] FIG. 5 is a diagram illustrating an example of communication setting parameters for FlexRay communication according to the first embodiment. [Figure 6] FIG. 6 is a diagram illustrating an example of the configuration of a star coupler according to the first embodiment. [Figure 7] FIG. 7 is a diagram showing an example of a frame list transmitted in FlexRay communication according to the first embodiment. [Figure 8] FIG. 8 is a diagram showing an example of a frame transmission schedule for FlexRay communication according to the first embodiment. [Figure 9] FIG. 9 is a diagram showing an example of the switching table according to the first embodiment. [Figure 10] FIG. 10 is a diagram showing an example of a sequence of switching communication according to the first embodiment. [Figure 11] FIG. 11 is a diagram showing the overall configuration of an in-vehicle network system according to the second embodiment. [Figure 12] FIG. 12 is a diagram illustrating an example of the configuration of an ECU according to the second embodiment. [Figure 13] FIG. 13 is a diagram illustrating an example of a switching table according to the second embodiment. [Figure 14]FIG. 14 is a diagram illustrating an example of a switching communication sequence according to the second embodiment. [Figure 15] FIG. 15 is a diagram showing an example of a switching table according to the third embodiment. [Figure 16] FIG. 16 is a diagram illustrating an example of the operation of the transmitting ECU in the third embodiment. [Figure 17] FIG. 17 is a diagram illustrating an example of the operation of the receiving ECU according to the third embodiment. [Figure 18] FIG. 18 is a diagram illustrating an example of the operation of the transmitting ECU in the modification of the third embodiment. [Figure 19] FIG. 19 is a diagram illustrating an example of the operation of the receiving ECU in the modification of the third embodiment. [Figure 20] FIG. 20 is a diagram illustrating an example of a frame list transmitted in FlexRay communication according to the fourth embodiment. [Figure 21A] FIG. 21A is a diagram illustrating an example of the operation of the transmitting ECU in the fourth embodiment. [Figure 21B] FIG. 21B is a diagram illustrating another example of the operation of the transmitting ECU in the fourth embodiment. [Figure 22] FIG. 22 is a diagram illustrating an example of the operation of the receiving ECU according to the fourth embodiment. [Figure 23] FIG. 23 is a diagram illustrating an example of the operation of the receiving ECU in the modification of the fourth embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0016] A fraud countermeasure method according to one aspect of the present disclosure is a fraud countermeasure method in an in-vehicle network, and includes a frame transmission / reception step for transmitting and receiving frames, a fraud detection step for detecting fraudulent frames, and a switching processing step for switching the transmission timing of the frame in which fraud is detected if fraud is detected in the fraud detection step, and in the switching processing step, the transmission timing of the switched-to destination is changed according to specified information.
[0017] This allows the transmission timing of the destination of switching (e.g., the slot ID of the destination of switching) to be dynamically determined, making it difficult for an attacker to predict the transmission timing of the destination of switching. In other words, correct frame information can be transmitted to another ECU at the transmission timing of the destination of switching. For example, compared to when the transmission timing of the destination of switching is determined by a simple table or the like, attacks on the destination of switching can be suppressed. Therefore, even if a fraudulent frame is transmitted to the in-vehicle network, the entire in-vehicle network system can be maintained in a safe state by detecting the fraudulent frame and taking action.
[0018] Furthermore, for example, the predetermined information includes the number of times of detection in the fraud detection step, and in the switching processing step, a transmission timing according to the number of times of detection is determined as the transmission timing of the switching destination.
[0019] This allows the transmission timing of the destination to be dynamically determined according to the number of errors. The number of errors can be synchronized between the transmitting and receiving ECUs.
[0020] Also, for example, the specified information includes information indicating the transmission time of the frame in which the fraud was detected, and in the switching processing step, the transmission timing of the destination is determined to be the transmission timing according to the information indicating the transmission time.
[0021] This allows the transmission timing of the destination to be dynamically determined according to the information indicating the transmission time. Note that the information indicating the transmission time can be synchronized between the transmitting and receiving ECUs.
[0022] Also, for example, in the switching processing step, a hash value of the number of detections is calculated, a remainder of the hash value is calculated using the number of bits of the payload segment of the frame in which the fraud was detected, and a transmission timing corresponding to the remainder is determined as the transmission timing of the switching destination.Also, for example, in the switching processing step, a pseudo-random number is generated using information indicating the transmission time as a seed, a remainder of the pseudo-random number is calculated using the number of bits of the payload segment of the frame in which the fraud was detected, and a transmission timing corresponding to the remainder is determined as the transmission timing of the switching destination.
[0023] This makes it more difficult for an attacker to predict the transmission timing of the destination, thereby improving the security of the in-vehicle network. Also, the calculated remainder value is smaller than the number of bits. For example, if the in-vehicle network is made up of FlexRay, it is possible to prevent the number of destination slots from increasing, thereby preventing the exhaustion of slot IDs.
[0024] Also, for example, the switching processing step further includes performing a bit shift operation on the bit string that constitutes the payload segment by a bit shift amount according to the remainder.
[0025] This allows the receiving ECU to easily determine whether the received frame is an unauthorized frame. For example, even if an attacker can predict the transmission timing after switching (e.g., slot ID), if the attacker does not know the bit shift rules, the decoded value of the unauthorized frame data frame decoded by the receiving ECU will be an unusual value. Therefore, by checking the decoded value, the receiving ECU can easily determine whether the frame is unauthorized.
[0026] Also, for example, the predetermined information includes a risk level of the frame in which the fraud was detected, and in the switching processing step, a transmission timing according to the risk level is determined as the transmission timing of the switching destination.
[0027] This allows the transmission timing of the destination to be dynamically determined according to the degree of danger. The degree of danger can be synchronized between the transmitting and receiving ECUs.
[0028] Also, for example, the switching process step is executed when the degree of risk is equal to or greater than a first threshold value.
[0029] This makes it possible to transmit correct information about high-risk frames to other ECUs while suppressing an increase in the amount of processing in the ECU.
[0030] Also, for example, in the switching processing step, if the risk level is equal to or higher than a first threshold, a bit shift calculation process is performed on the bit string that constitutes the payload segment of the frame in which the fraud was detected, using a bit shift amount corresponding to the risk level.
[0031] This allows the receiving ECU to easily determine whether the received frame is an unauthorized frame.
[0032] Also, for example, in the switching processing step, if the risk level is equal to or greater than a second threshold value that is lower than the first threshold value and is less than the first threshold value, a bit shift operation is performed on the bit string that constitutes the payload segment using a bit shift amount that corresponds to the risk level.
[0033] This makes it possible to easily determine whether a frame is an unauthorized frame in the receiving ECU while suppressing an increase in the amount of processing in the ECU.
[0034] Also, for example, in the switching processing step, when the degree of risk is equal to or greater than a third threshold higher than the first threshold, a plurality of transmission timings according to the degree of risk are determined as the transmission timing to be switched to.
[0035] This makes it even more difficult to predict the transmission timing of the switching destination.
[0036] Also, for example, the predetermined information includes a vehicle state of the vehicle, and in the switching processing step, a transmission timing according to the vehicle state is determined as the transmission timing of the switching destination.
[0037] This allows the timing of switching transmission to be dynamically determined according to the vehicle state. The vehicle state can be synchronized between the transmitting and receiving ECUs.
[0038] Furthermore, for example, the switching process step is executed when the number of detections in the fraud detection step is equal to or greater than a predetermined number, or when the elapsed time since the last fraud detection is equal to or less than a predetermined time.
[0039] This allows the transmission timing to be switched when the unauthorized state continues, thereby effectively maintaining a safe state in the vehicle.
[0040] Also, for example, in the switching processing step, the frame transmission timing is switched after the frame in which the fraud was detected is transmitted at the transmission timing of the frame.
[0041] This allows the same frame to be transmitted multiple times, and the receiving ECU can determine whether at least one of the multiple frames is an unauthorized frame based on the differences between the multiple frames.
[0042] Also, for example, the communication method in the in-vehicle network is a time-triggered communication method based on time slots, and in the frame transmission / reception step, frames are transmitted and received within predetermined time slots, and in the switching processing step, the destination slot is determined as the transmission timing of the destination.
[0043] As a result, when the communication method of the in-vehicle network system is FlexRay, the in-vehicle network system as a whole can be maintained in a safe state.
[0044] Also, for example, the time slots include a plurality of free slots to which no frame is assigned, and in the switching processing step, a free slot according to the predetermined information is determined as a slot to be switched to.
[0045] This allows the in-vehicle network system as a whole to maintain a safe state without affecting the transmission of other frames.
[0046] In addition, a fraud prevention device according to one aspect of the present disclosure is a fraud prevention device in an in-vehicle network, and includes a frame transmission / reception unit that transmits and receives frames, a fraud detection unit that detects fraudulent frames, and a switching processing unit that switches the transmission timing of a frame in which fraud is detected when fraud is detected by the fraud detection unit, and the switching processing unit changes the transmission timing of the destination according to specified information.
[0047] This provides the same effect as the fraud prevention method described above.
[0048] Hereinafter, fraud prevention methods and the like according to embodiments of the present disclosure will be described with reference to the drawings. Each of the embodiments described below represents a preferred specific example of the present disclosure. In other words, the numerical values, shapes, materials, components, component arrangements and connection forms, steps, and step order shown in the following embodiments are examples of the present disclosure and are not intended to limit the present disclosure. The present disclosure is defined by the claims. Therefore, among the components in the following embodiments, components not recited in the independent claims that represent the superordinate concept of the present disclosure are not necessarily required to achieve the objectives of the present disclosure, but are described as components that constitute more preferred embodiments.
[0049] Furthermore, each figure is a schematic diagram and is not necessarily an exact illustration. Therefore, for example, the scales of the figures do not necessarily match. Furthermore, in each figure, substantially the same components are given the same reference numerals, and redundant explanations are omitted or simplified.
[0050] (Embodiment 1) [1. System Configuration] Here, an in-vehicle network system 10 will be described as an embodiment of the present disclosure with reference to the drawings.
[0051] [1-1. Overall Configuration of In-Vehicle Network System 10] FIG. 1 is a diagram showing the overall configuration of an in-vehicle network system 10 according to a first embodiment. The in-vehicle network system 10 includes FlexRay buses 100a, 100b, 100c, and 100d; ECUs 200a, 200b, 200c, and 200d connected to the respective buses; a front camera 210, a gear 220, a brake 230, and a rear camera 240, which are controlled by the respective ECUs; and a star coupler 300 connecting the respective FlexRay buses. The ECUs 200a to 200d control the vehicle by transmitting and receiving frames via the FlexRay buses. The star coupler 300 also shapes signals on the FlexRay buses 100a, 100b, 100c, and 100d so that the same signals flow through all of the buses, and the ECUs are synchronized via the FlexRay buses.
[0052] [1-2. FlexRay Cycle] 2 is a diagram showing a cycle of FlexRay communication in embodiment 1. FlexRay communication is performed in units called cycles, and each node synchronously holds the number of cycle repetitions (cycle counter), with the cycle counter taking values from 0 to 63. If the cycle counter is 63, the cycle counter is reset to 0 in the next cycle.
[0053] Each cycle consists of four segments: static segment, dynamic segment, symbol window, and network idle time (NIT). The time for each segment is common to the entire FlexRay network (cluster) according to pre-designed parameters, so the time for one cycle is also common to the cluster.
[0054] A static segment consists of multiple slots. The number of slots and the time of each slot are common within the cluster. Furthermore, one FlexRay frame is transmitted within one slot, and the slot number becomes the frame identifier (Frame ID). Each ECU is designed to transmit frames at a predetermined timing (slot number). Frames transmitted within a static segment are called static frames. The payload length of static frames is common within the cluster.
[0055] Dynamic segments are made up of slots called minislots. Minislots also have slot numbers, and each ECU is designed to transmit at a predetermined timing (slot number), but unlike static segments, it is not necessary to transmit frames. Frames transmitted within dynamic segments are called dynamic frames. Dynamic frames can have any value between 0 and 254 as their payload length.
[0056] The symbol window is a time period during which signals called symbols are transmitted and received.
[0057] Network idle time is a period of time when no communication takes place, and is always set at the end of a cycle. Each ECU performs time synchronization and other processes.
[0058] [1-3. Frame format] Fig. 3 is a diagram showing a frame format of FlexRay communication in embodiment 1. Specifically, Fig. 3 is a diagram showing a frame format of the FlexRay protocol. The frame includes three segments: a header segment, a payload segment, and a trailer segment.
[0059] The Header Segment begins with a Reserved bit and contains one bit each of the following to indicate the frame type: Payload preamble indicator, Null frame indicator, Sync frame indicator, and Startup frame indicator. The Header Segment also contains an 11-bit Frame ID, a 7-bit Payload length, an 11-bit Header CRC, and a 6-bit Cycle count. The Frame ID, also known as the Slot ID, is used to identify the frame transmission timing and frame contents. The Payload length can have a value of up to 127. The Payload Segment stores the number of bytes obtained by multiplying the Payload length value by 2. The Header CRC is a checksum calculated from the value from the Sync frame indicator to the Payload length. The Cycle count stores the current cycle number. The cycle number is an example of information indicating the transmission time.
[0060] The Payload Segment contains data representing the contents of the frame. It contains twice the number of bytes as the Payload Length, up to a maximum of 254 bytes.
[0061] The Trailer Segment contains a CRC calculated from values including the entire frame.
[0062] [1-4. ECU200a configuration diagram] 4 is a diagram showing an example of the configuration of the ECU 200a in the first embodiment. Note that the ECUs 200b, 200c, and 200d have the same configuration, and therefore their description will be omitted here.
[0063] The ECU 200a includes a frame transmission / reception unit 201, a communication setting parameter storage unit 202, a frame interpretation unit 203, an external device control unit 204, a frame generation unit 205, a fraud determination unit 206, a switching determination unit 207, and a switching table storage unit 208.
[0064] The frame transmitting / receiving unit 201 acquires frame information by decoding a physical signal received from the bus 100a into a digital signal. The frame transmitting / receiving unit 201 can synchronize time with other ECUs and correctly receive frames by referring to communication setting parameters stored in the communication setting parameter storage unit 202. Furthermore, the frame transmitting / receiving unit 201 converts the frame into a physical signal at a predetermined timing and transmits it to the bus 100a in accordance with a transmission frame request notified by the frame generating unit 205.
[0065] The communication setting parameter storage unit 202 stores parameters common to the cluster for correctly converting physical signals into digital signals. An example of the communication setting parameters stored in the communication setting parameter storage unit 202 is shown in Fig. 5, and will be described in detail later.
[0066] The frame interpretation unit 203 interprets the payload included in the received frame notified from the frame transmission / reception unit 201, and notifies the external device control unit 204 to control the front camera 210 connected to the ECU 200a according to the contents of the payload. The frame interpretation unit 203 determines the driving state based on, for example, information about the vehicle speed notified from another ECU, and adjusts the contents of the camera shot according to the driving state. The frame interpretation unit 203 also notifies the fraud determination unit 206 of the received contents, such as the ID and payload, included in the frame.
[0067] The external device control unit 204 controls the front camera 210 connected to the ECU 200a. In addition, the external device control unit 204 notifies the frame generation unit 205 of a frame transmission request for notifying other ECUs of the state in accordance with the content of notification from the front camera 210. For example, the external device control unit 204 notifies the frame generation unit 205 of the presence or absence of a pedestrian ahead.
[0068] The frame generating unit 205 generates a frame based on the notified signal and issues a transmission request to the frame transmitting / receiving unit 201 .
[0069] The fraud determination unit 206 determines whether a received frame is fraudulent based on the received contents such as the ID and payload notified from the frame interpretation unit 203. In this embodiment, if an error such as a syntax error is received with the same ID, the frame is determined to be fraudulent. If the fraud determination unit 206 determines that the frame is fraudulent, it notifies the switching determination unit 207 and the frame generation unit 205 to that effect. The fraud determination unit 206 is an example of a fraud detection unit.
[0070] Based on the determination result notified by the fraud determination unit 206, the switching determination unit 207 refers to the contents of the switching table notified by the switching table holding unit 208, and notifies the frame generation unit 205 to change the transmission contents.
[0071] The switching table storage unit 208 stores a switching table required for switching the content of transmission depending on the fraud detection result.
[0072] [1-5. Example of communication setting parameters] FIG. 5 is a diagram illustrating an example of communication setting parameters for FlexRay communication in the first embodiment. The communication setting parameters illustrated in FIG. 5 are stored in the communication setting parameter storage unit 202. In the example of FIG. 5, the communication setting parameters include a baud rate indicating the communication speed of 10 Mbps, slot IDs of static segments ranging from 1 to 50, and slot IDs of dynamic segments ranging from 51 to 100. It is also indicated that the payload length of the static slot is 8 (i.e., 16 bytes). These values are shared by all ECUs in the cluster, and FlexRay frames are transmitted and received based on these values. Note that the values of the communication setting parameters are merely examples, and other values may be used. Furthermore, the parameters illustrated here are merely examples, and parameters not illustrated in FIG. 5 (e.g., the length of each segment, the length of a slot, etc.) may be included, or conversely, some of the illustrated parameters may not be included.
[0073] [1-6. Star coupler 300 configuration diagram] 6 is a diagram showing an example of the configuration of star coupler 300 in embodiment 1. Star coupler 300 has transceiver units 301a, 301b, 301c, and 301d, and a routing unit 302. Note that transceiver units 301b, 301c, and 301d have the same configuration as transceiver unit 301a, and therefore their description will be omitted.
[0074] The transceiver unit 301a converts a physical signal received from the bus 100a into a digital signal and notifies the routing unit 302. When the transceiver unit 301a is notified of a digital signal from the routing unit 302, the transceiver unit 301a converts the notified digital signal into a physical signal and transfers it to the bus 100a.
[0075] Routing unit 302 transfers the digital signal notified from transceiver unit 301a to transceiver units 301b, 301c, and 301d excluding transceiver unit 301a. Similarly, when routing unit 302 is notified of a digital signal from transceiver unit 301b, it notifies the transceiver units excluding transceiver unit 301b of the digital signal. When routing unit 302 receives digital signals from multiple transceiver units, it notifies the other transceiver units of the signal from the bus that first received the digital signal.
[0076] [1-7. Example of a frame list] Fig. 7 is a diagram showing an example of a frame list transmitted in FlexRay communication in embodiment 1. For example, Fig. 7 shows an example of a frame list transmitted and received by the ECU 200a.
[0077] In Figure 7, the frame list contains the slot ID, cycle offset, cycle reception, frame name, and payload information included in the frame. Cycle offset and cycle reception are necessary information for extracting the target frame when cycle multiplexing, a method of transmitting and receiving frames with different contents even if they have the same slot ID, is used. For example, a frame with slot ID 98 has two frame names, each of which reports different contents: front camera information 1 and front camera information 2. For front camera information 1, the cycle offset is 0 and the cycle reception is 2. This means that the cycle counter starts from 0 and the frame is transmitted every two cycles. In other words, frame C reporting front camera information 1 is transmitted when the slot ID of the cycle counter is 0, 2, 4, 6, . . . , 58, 60, and 62 is 98. Similarly, frame D containing front camera information 2 is transmitted when the slot ID of the cycle counter is 1, 3, 5, . . . , 59, 61, and 63 is 98. The method of transmitting different frames with the same slot ID as above is called cycle multiplexing. Similarly, the frame with slot ID 99 also has two frame names, each of which notifies different content: rear camera information 1 and rear camera information 2. Frame E, which contains rear camera information 1, is transmitted when the cycle counter is 0, 2, 4, ..., 58, 60, 62 and the cycle ID is 99, and frame F, which contains rear camera information 2, is transmitted when the cycle counter is 1, 3, 5, ..., 59, 61, 63 and the cycle ID is 99.
[0078] In FIG. 7, a frame with a slot ID of 1, a cycle offset of 0, and a cycle reception of 1 (i.e., the same frame is transmitted in every cycle) has a frame name of A, which indicates that the payload of frame A contains information about speed. A slot ID of 2 indicates that no frame is transmitted. A frame with a slot ID of 3, a cycle offset of 0, and a cycle reception of 2 (i.e., transmitted only when the cycle counter is an even number) has a frame name of B, which indicates that the payload of frame B contains information about the gear state. A frame with a slot ID of 98, a cycle offset of 0, and a cycle reception of 2 has a frame name of C, which indicates that the payload of frame C contains information about front camera information 1. A frame with a slot ID of 98, a cycle offset of 1, and a cycle reception of 2 has a frame name of D, which indicates that the payload of frame D contains information about front camera information 2. A frame with a slot ID of 99, a cycle offset of 0, and a cycle reception of 2 has a frame name of E, which indicates that the payload of frame E contains information about rear camera information 1. A frame with a slot ID of 99, a cycle offset of 1, and a cycle reception of 2 has a frame name of F, and the payload of frame F contains information about rear camera information 2. Furthermore, frames A and B are static frames transmitted within the static segment, and frames C to F are dynamic frames transmitted within the dynamic segment.
[0079] Fig. 8 is a diagram showing an example of a frame transmission schedule for FlexRay communication in the first embodiment. Fig. 8 shows a frame transmission schedule for the example frame list in Fig. 7. The horizontal axis indicates the slot ID, and the vertical axis indicates the cycle. The name of the frame to be transmitted is written in a cell determined by the slot ID and the cycle. In Fig. 8, frames C to F are transmitted in a predetermined cycle, but since these frames are dynamic frames, they may not be transmitted.
[0080] [1-8. Example of a switching table] 9 is a diagram showing an example of a switching table in embodiment 1. In this embodiment, when fraud occurs in frames with IDs of 1, 3, 98, and 99, the IDs are switched to 97, 100, 99, and 98, respectively.
[0081] [1-9. Example of switching communication sequence] Fig. 10 is a diagram showing an example of a sequence of switching communication in the embodiment 1. For example, Fig. 10 shows an example of a sequence in which the ECU 200a detects fraud and performs switching.
[0082] (S1001) The ECU 200a detects whether or not there is an error in FlexRay.
[0083] (S1002) The ECU 200a determines whether an error due to the same ID has occurred multiple times using a counter for determining whether an error due to the same ID has occurred.
[0084] (S1003) The ECU 200a counts up the error counter for the target ID.
[0085] (S1004) The ECU 200a refers to the switching table and finds the switching process corresponding to the target ID.
[0086] (S1005) The ECU 200a switches the ID setting.
[0087] (S1006) The ECU 200a clears the error counter for the target ID.
[0088] [1-10. Effects of the First Embodiment] In the fraud prevention method described in the first embodiment, an ECU that detects fraud uses a switching table to dynamically change the transmission slot of the frame to be transmitted, thereby avoiding communication interference caused by fraudulent frames and maintaining normal communication. Furthermore, by effectively utilizing communication slots that have been reserved in advance, it is possible to transmit frames without increasing the communication volume.
[0089] (Embodiment 2) [2. System Configuration] Here, an in-vehicle network system 20 will be described as an embodiment of the present disclosure with reference to the drawings.
[0090] [2-1. Overall Configuration of In-Vehicle Network System 20] 11 is a diagram showing the overall configuration of an in-vehicle network system 20 according to the second embodiment. The in-vehicle network system 20 includes FlexRay buses 100a, 100b, 100c, and 100d, ECUs 1200a, 1200b, 1200c, and 1200d connected to the respective buses, a front camera 210, a gear 220, a brake 230, and a rear camera 240 controlled by the respective ECUs, and a star coupler 300 connecting the respective FlexRay buses. Note that the same components as those in the first embodiment are given the same numbers, and description thereof will be omitted.
[0091] [2-2.ECU1200a configuration diagram] 12 is a diagram showing an example of the configuration of an ECU 1200a in the embodiment 2. Note that ECU 1200b, ECU 1200c, and ECU 1200d have the same configuration, and therefore description thereof will be omitted here.
[0092] The ECU 1200a includes a frame transmitting / receiving unit 201, a communication setting parameter holding unit 202, a frame interpretation unit 1203, an external device control unit 204, a frame generation unit 205, a fraud determination unit 206, a switching determination unit 1207, a switching table holding unit 208, and a vehicle state determination unit 1209. Note that the same components as those in the first embodiment are given the same numbers, and descriptions thereof will be omitted.
[0093] The frame interpretation unit 1203 interprets the payload included in the received frame notified from the frame transmission / reception unit 201, and notifies the external device control unit 204 to control the front camera 210 connected to the ECU 1200a according to the contents of the payload. For example, the frame interpretation unit 1203 determines the driving state based on information about the vehicle speed notified from another ECU, and adjusts the camera's image capture content according to the driving state. The frame interpretation unit 1203 also notifies the fraud determination unit 206 and the vehicle state determination unit 1209 of the received contents, such as the ID and payload included in the frame.
[0094] Based on the judgment result notified from the fraud judgment unit 206 and the vehicle state notified from the vehicle state judgment unit 1209, the switching judgment unit 1207 refers to the contents of the switching table notified from the switching table holding unit 208 and notifies the frame generation unit 205 to change the transmission content.
[0095] The vehicle state determination unit 1209 determines the current vehicle state based on received contents such as the ID and payload notified from the frame interpretation unit 1203. For example, a frame including the result of determination by another ECU as a payload may be received, or the vehicle state determination unit 1209 of each ECU may make a determination based on information such as speed and gear.
[0096] [2-3. Example of a switching table] 13 is a diagram showing an example of a switching table in embodiment 2. In this embodiment, the IDs 1 and 3 are switched to IDs 97 and 100, respectively, regardless of the state of the vehicle. Also, the IDs 98 and 99 are switched to IDs 99 and 98, respectively, only when the vehicle is moving.
[0097] [2-4. Example of switching communication sequence] Fig. 14 is a diagram showing an example of a sequence of switching communication in the second embodiment. For example, Fig. 14 shows an example of a sequence in which ECU 1200a detects fraud and performs switching. Note that the same processing steps as those in Fig. 10 are given the same numbers, and descriptions thereof will be omitted.
[0098] (S2007) ECU 1200a compares the current vehicle state with the switching table and determines whether the target ID needs to be switched. That is, ECU 1200a determines whether the current vehicle state is a vehicle state that requires switching. If ECU 1200a determines that the current vehicle state is a vehicle state that requires switching (Yes in S2007), the process proceeds to step S1005, and if ECU 1200a determines that the current vehicle state is not a vehicle state that requires switching (No in S2007), the process proceeds to step S1006.
[0099] [2-5. Effects of the Second Embodiment] In the fraud prevention method described in the second embodiment, an ECU that detects fraud dynamically changes the transmission slot of a frame to be transmitted using a switching table corresponding to a specific vehicle state, thereby avoiding communication interference caused by fraudulent frames and maintaining normal communication. Furthermore, by effectively utilizing communication slots that have been freed up in advance, frames can be transmitted without increasing the amount of communication. Furthermore, by limiting the vehicle state to a specific one, changes from normal communication can be minimized, allowing normal communication to be maintained.
[0100] (Effects of the first and second embodiments) A fraud prevention method according to one embodiment of the present disclosure is a fraud prevention method for an in-vehicle network that is a time-triggered communication method based on time slots, in which one or more electronic control units (e.g., ECU 200a) are connected to in-vehicle network systems 10 and 20, and each electronic control unit transmits and receives frames within a predetermined time slot. The fraud prevention method for the electronic control unit includes a frame transmission / reception step for transmitting and receiving frames, a fraud detection step (e.g., S1001) for detecting fraudulent frames, and a switching determination step (e.g., S1005) for performing switching processing of the transmitted frame in accordance with predetermined settings when predetermined conditions are met based on the determination result of the fraud detection step.
[0101] As a result, when an unauthorized frame is detected, the in-vehicle network systems 10 and 20 can be switched over to maintain a safe state as a whole.
[0102] Furthermore, in the fraud detection step, the fraud countermeasure method according to one aspect of the present disclosure determines whether a frame is fraudulent using a predetermined attack determination algorithm.
[0103] As a result, even if the in-vehicle network is subjected to a cybersecurity attack, the in-vehicle network systems 10 and 20 as a whole can be maintained in a safe state.
[0104] Furthermore, in the fraud handling method according to one aspect of the present disclosure, as a predetermined setting, either a static slot or a dynamic slot is designated as the slot from which to switch.
[0105] This makes it possible to avoid a situation where a frame in a particular slot cannot be transmitted even if the slot becomes invalid.
[0106] Furthermore, in the fraud handling method according to one aspect of the present disclosure, for example, as a predetermined setting, either a static slot or a dynamic slot is designated as the slot to be switched to.
[0107] This makes it possible to avoid a situation where a frame in a particular slot cannot be transmitted even if the slot becomes invalid.
[0108] Furthermore, in the fraud handling method according to one aspect of the present disclosure, for example, a predetermined setting is to specify an empty slot to which no frame has yet been allocated as the switching destination slot.
[0109] This allows communication to be carried out without increasing the overall communication time.
[0110] Furthermore, in the fraud handling method according to one aspect of the present disclosure, for example, a slot to which a frame has already been allocated is designated as the destination slot as a predetermined setting.
[0111] This makes it possible to carry out communication without increasing the overall communication time, even in the case of communication specifications where there are no free slots to begin with.
[0112] Furthermore, the fraud countermeasure method according to one aspect of the present disclosure combines, as a predetermined setting, the payload of an already assigned frame with the payload of a switched frame, for example.
[0113] This makes it possible to carry out communication without increasing the overall communication time.
[0114] Furthermore, in a fraud prevention method according to an aspect of the present disclosure, for example, a new slot is added to the destination slot as a predetermined setting.
[0115] This allows communication to be carried out without relying on normal communication specifications.
[0116] Furthermore, a fraud prevention method according to an aspect of the present disclosure may, for example, be configured to exchange the payload of an already assigned frame with the payload of a switched frame as a predetermined setting.
[0117] This makes it possible to transmit and receive information that would normally require transmitting and receiving a frame of multiple slots simply by transmitting and receiving a specific payload.
[0118] Furthermore, the fraud handling method according to one aspect of the present disclosure performs a switching process by, for example, detecting the occurrence of an error according to the communication method as a predetermined condition.
[0119] This makes it possible to perform the switching process without the need to prepare an additional notification frame.
[0120] Furthermore, the fraud handling method according to one aspect of the present disclosure performs switching processing by, for example, detecting a frame other than the frame in which fraud has occurred as a predetermined condition.
[0121] This allows the switching process to be performed independently of the network protocol.
[0122] Furthermore, the fraud prevention method according to one aspect of the present disclosure performs a switching process depending on, for example, the state of a vehicle equipped with a pre-set in-vehicle network as a predetermined condition.
[0123] This makes it possible to define an appropriate switching process depending on the vehicle state, thereby minimizing the difference from normal conditions.
[0124] Furthermore, the state of the vehicle in the fraud prevention method according to one aspect of the present disclosure is one of the following states: parked, stopped, or moving.
[0125] This makes it possible to specify appropriate switching processing depending on whether the vehicle is parked, stopped, or moving, thereby minimizing the difference from normal times.
[0126] Furthermore, there is provided a communication system in an in-vehicle network that is a time-triggered communication method based on time slots, in which one or more electronic control devices are connected to the in-vehicle network, and each electronic control device transmits and receives frames within a predetermined time slot, and the electronic control device has a frame transmission / reception step that transmits and receives frames, a fraud detection step that detects fraudulent frames, and a switching determination step that performs switching processing of the transmitted frame in accordance with predetermined settings when predetermined conditions are met based on the determination result of the fraud detection step.
[0127] This allows the in-vehicle network system as a whole to maintain a safe state by switching when an unauthorized frame is detected.
[0128] Furthermore, in a communication system for an in-vehicle network that is a time-triggered communication method based on time slots, one or more electronic control units are connected to the in-vehicle network, and each electronic control unit transmits and receives frames within a predetermined time slot. The electronic control unit includes a frame transmitting / receiving unit 201 that transmits and receives frames, a fraud determination unit 206 that detects fraudulent frames, and a switching determination unit 207 that performs switching processing of transmitted frames in accordance with predetermined settings when predetermined conditions are met based on the determination result of the fraud detection step.
[0129] This allows the in-vehicle network system as a whole to maintain a safe state by switching when an unauthorized frame is detected.
[0130] (Embodiment 3) [3-1. System Configuration] In this embodiment, a case will be described in which when the slot ID of a frame in which fraud is detected is switched, the slot ID of the switching destination changes dynamically. Specifically, a case will be described in which the slot ID of the switching destination of the slot ID in which fraud is detected changes dynamically based on the number of times fraud is detected (number of errors). Note that the number of errors is, for example, the number of times fraud is detected in the same slot ID.
[0131] The configuration of the in-vehicle network system according to this embodiment is the same as the in-vehicle network system 10 according to embodiment 1 or the in-vehicle network system 20 according to embodiment 2, and therefore a description thereof will be omitted. In the following, an example will be described in which the configuration of the in-vehicle network according to this embodiment is the same as the in-vehicle network system 10 according to embodiment 1.
[0132] First, the information stored in the in-vehicle network system 10 will be described with reference to Fig. 15. Fig. 15 is a diagram showing an example of a switching table in the third embodiment. In this embodiment, as shown in Fig. 9 etc., there is no one-to-one correspondence between the ID before change and the ID after change. The ID after change changes dynamically based on predetermined conditions.
[0133] As shown in FIG. 15, the switching table includes a switching rule number, a bit shift number of a payload segment, and an increment number of a slot ID.
[0134] The switching rule number is a number for identifying the number of bit shifts of a payload segment and the number of increments of a slot ID. The number of bit shifts of one payload segment and the number of increments of one slot ID are set for one switching rule number. In this embodiment, the switching rule number is a value corresponding to the remainder Re, which will be described later.
[0135] The bit shift number of a payload segment indicates the amount of bit shift when a bit shift operation is performed on a bit string that constitutes a payload segment (see FIG. 3). For example, a different bit shift number is set for each switching rule number. The bit shift number may be the number of bit shifts when a right shift is performed in the bit shift operation, or the number of bit shifts when a left shift is performed. In other words, the bit shift operation may be a right shift or a left shift. In the following, an example will be described in which the bit shift operation is a process that performs a right shift. For example, a switching rule of "1" means that the bit string of the payload segment is shifted one bit to the right. Furthermore, the bit shift operation is performed, for example, by a cyclic shift operation.
[0136] The increment number of the slot ID is information for determining the destination slot ID. For example, different increment numbers of the slot ID are set for each switching rule number. For example, the increment number of the slot ID corresponding to switching rule "0" is "0". In this case, it is set to a preset slot ID. In the following, it is assumed that the slot ID of the preset slot is 100. Also, the increment number of the slot ID corresponding to switching rule "1" is "1". In this case, the destination ID of the switching is set to 101, which is 100, the slot ID of the preset slot.
[0137] In the case of FIG. 15, the increment of the slot ID is "0" to "N", and the corresponding destination slot ID is "100" to "100+N". Here, each destination slot ID is the slot ID of an empty slot to which no frame has yet been assigned. The destination slot ID may also be selected from, for example, a dynamic frame. The advantage of a dynamic frame is that the payload length can be set to any value.
[0138] 15, an example has been described in which the slot ID increases by one in accordance with the switching rule number, but this is not limited to this as long as it is different for each switching rule number. The slot ID of the switching destination may increase by multiples (for example, by two). Furthermore, the increase number does not have to be the same for each switching rule number (for example, by one). Furthermore, the increase number may be a negative value.
[0139] The switching table shown in FIG. 15 is stored in the switching table storage unit 208, for example.
[0140] [3-2. System Operation] Next, the operation of the in-vehicle network system 10 according to the present embodiment will be described with reference to Fig. 16 and Fig. 17. Fig. 16 is a diagram showing an example of the operation of the transmitting ECU according to the third embodiment.
[0141] As shown in FIG. 16, the frame generating unit 205 generates a frame for notifying other ECUs of their status based on a signal notified from the external device control unit 204 (S3001).
[0142] Based on the result of fraud determination from fraud determination unit 206, switching determination unit 207 determines whether the number of errors is equal to or greater than a predetermined number. In this embodiment, switching determination unit 207 determines whether the number of errors is "0" (S3002). That is, switching determination unit 207 determines whether an error has occurred. The number of errors is an example of the number of detections.
[0143] When switching determination unit 207 determines that the number of errors is "0", that is, that no error has occurred (Yes in S3002), it notifies (outputs) information indicating that there is no error to frame generation unit 205. Frame generation unit 205 outputs a transmission frame request to frame transceiver unit 201 to transmit the generated frame. Frame transceiver unit 201 transmits the frame together with the transmission time in accordance with the transmission frame request output from frame generation unit 205 (S3003). Frame transceiver unit 201 transmits a frame including, for example, the transmission time.
[0144] Furthermore, when switching determination unit 207 determines that the number of errors is not "0", that is, that an error has occurred (No in S3002), it references the contents of a switching table (for example, the switching table shown in FIG. 15) stored in switching table holding unit 208, and outputs a command to frame generation unit 205 to change the transmission contents. Changing the transmission contents includes, for example, at least one of performing a bit shift operation and switching the slot ID.
[0145] When frame generation unit 205 receives information indicating a change in transmission content from switching determination unit 207, it calculates a hash value of the number of errors (S3004) and calculates a remainder Re of the hash value using the number of bits L of the payload segment (S3005). Then, frame generation unit 205 executes different processes depending on the calculated remainder Re (S3006 to S3013). Note that the hash function for calculating the hash value is stored in, for example, switching table storage unit 208. Also, the number of bits L is not particularly limited, but is, for example, 64 bits. In this case, the maximum value of remainder Re is 63.
[0146] In this way, by using the remainder Re obtained by dividing the hash value by the number of bits L, it is possible to prevent the slot ID of the switching destination from being depleted. Note that in step S3004, the hash value is not limited to being divided by the number of bits L, and may be divided by, for example, a predetermined numerical value. The predetermined numerical value may be determined appropriately depending on, for example, the number of available slots. Furthermore, the method of calculating the remainder Re is not limited to division, and may include addition, subtraction, multiplication, etc.
[0147] If the remainder Re is 0, the frame generation unit 205 changes the slot ID to a preset free slot ID (slot ID 100 in the example of FIG. 16) (S3007). For example, the frame generation unit 205 switches a frame that would normally be transmitted with slot ID "1" to slot ID "100" and transmits it. In this way, for example, if the remainder Re is 0, the frame generation unit 205 executes only the slot ID change process out of the bit shift operation process and the slot ID change process.
[0148] Furthermore, frame generation unit 205 executes a bit shift operation process and a slot ID change process when remainder Re is equal to or greater than 1. That is, when remainder Re is equal to or greater than 1, frame generation unit 205 executes a process for transmitting a frame obtained by performing a bit shift operation process on a payload segment included in the frame generated in step S3001, with a slot ID different from the slot ID corresponding to the frame.
[0149] For example, if the remainder Re is 1, the frame generation unit 205 shifts the payload segment to the right by 1 (S3008) and increments the destination slot ID by 1 (S3009). In this case, the destination slot ID becomes "101", which is the slot ID set in step S3007 plus 1.
[0150] Also, for example, when the remainder Re is 2, frame generation unit 205 shifts the payload segment to the right by 2 (S3010) and increments the destination slot ID by 2 (S3011). In this case, the destination slot ID becomes slot ID "102", which is obtained by adding 2 to the slot ID set in step S3007.
[0151] Furthermore, for example, when the remainder Re is L-1, the frame generation unit 205 shifts the payload segment to the right by L-1 (S3012) and increments the destination slot ID by L-1 (S3013). In this case, the slot ID "100+L-1" obtained by adding L-1 to the slot ID set in step S3007 becomes the destination slot ID.
[0152] In this way, in this embodiment, the number of errors is also an example of predetermined information for determining the slot ID of the switching destination.
[0153] Then, the frame generating unit 205 transmits the frame that has been subjected to the bit shift operation together with the transmission time at the transmission timing of the slot ID (empty slot ID) of the switching destination (S3003).
[0154] In addition, in FIG. 16, an example has been described in which the shift amount of the payload segment and the increase amount of the slot ID are the same value as the value of the remainder Re, but this is not limited to this, and it is sufficient that at least one of the shift amount of the payload segment and the increase amount of the slot ID is different for each remainder Re.
[0155] 16, an example is described in which a frame is transmitted using the slot ID of the new slot when the number of errors is not 0, but the frame may also be transmitted using the slot ID before switching. In other words, frame generation unit 205 may transmit the same frame using two or more slot IDs.
[0156] 16, an example of calculating a hash value from the number of errors has been described, but the present invention is not limited to this, and the amount of shift of the payload segment and the amount of increase in the slot ID may be determined directly according to the value of the number of errors. For example, when the number of errors is 1, the same processing as when the remainder Re is 1 may be performed.
[0157] Although the above example shows a case where a frame including the transmission time is transmitted in step S3003, this is not limiting. The transmission time may be transmitted in a separate frame. For example, the transmission time may be transmitted to another ECU in a slot ID that is transmitted at a transmission timing earlier than the slot ID assigned when step S3002 is determined to be No. Furthermore, the number of errors may also be transmitted in the slot ID. This allows the transmission time and the number of errors to be synchronized (the transmission time and the number of errors are shared) between the transmitting and receiving ECUs. Furthermore, the receiving ECU can predict the slot ID to which it will switch in advance by receiving information for predicting the slot ID (at least one of the transmission time and the number of errors).
[0158] Next, the operation of an ECU that receives a frame in the in-vehicle network system 10 according to the present embodiment will be described with reference to Fig. 17. Fig. 17 is a diagram showing an example of the operation of an ECU on the receiving side according to the third embodiment.
[0159] 17, the frame transmitting / receiving unit 201 receives the frame transmitted in step S3003 (S3101). The frame transmitting / receiving unit 201 outputs the received frame to the frame interpretation unit 203.
[0160] The frame interpretation unit 203 determines whether the number of errors corresponding to the slot ID of the received frame is equal to or greater than a predetermined number. For example, the frame interpretation unit 203 determines whether the number of errors at the transmission time is equal to or greater than a predetermined number. In this embodiment, the frame interpretation unit 203 determines whether the number of errors is "0" (S3102). In other words, the frame interpretation unit 203 determines whether an error has occurred in the slot ID.
[0161] If the frame interpretation unit 203 determines that the number of errors is "0", that is, that no error has occurred (Yes in S3102), it reads and processes the data frame (S3103). The frame interpretation unit 203 interprets the payload included in the frame and notifies the external device control unit 204 to control a device connected to the ECU (for example, the front camera 210 in the case of ECU 200a) according to the contents of the payload.
[0162] Furthermore, if frame interpretation unit 203 determines that the number of errors is not "0", that is, that an error has occurred (No in S3102), it executes the reverse process (correction process) of steps S3007 to S3013. That is, frame interpretation unit 203 executes the process of undoing the bit shift (process of correcting the bit position) and the process of undoing the slot ID.
[0163] Specifically, frame interpretation unit 203 calculates a hash value of the number of errors at the transmission time included in the frame (S3104). The number of errors here is the same value as the number of errors used in step S3004. Therefore, the hash value calculated in step S3104 is the same value as the hash value calculated in step S3004.
[0164] Next, frame interpretation unit 203 calculates the remainder Re of the hash value using the number of bits L of the payload segment (S3105). Here, remainder Re is the same value as remainder Re calculated in step S3005. Then, frame interpretation unit 203 executes different processes depending on the calculated remainder Re (S3106 to S3113).
[0165] When the remainder Re is 0, the frame interpretation unit 203 changes the frame transmitted with the slot ID "100" to the original slot ID (S3107), as a process corresponding to step S3007. In this way, when the remainder Re is 0, for example, the frame interpretation unit 203 executes only the process of restoring the slot ID out of the process of restoring the bit shift and the process of restoring the slot ID.
[0166] For example, frame interpretation unit 203 changes slot ID "100" to slot ID "1," which is the original slot ID. That is, frame interpretation unit 203 can recognize that a frame received with slot ID "100" is a frame that should have been transmitted with slot ID "1." Based on the frame list shown in FIG. 7, for example, frame interpretation unit 203 can recognize that the frame received with slot ID "100" is a frame that includes a speed.
[0167] Furthermore, if the remainder Re is 1 or greater, the frame interpretation unit 203 executes a process of undoing the bit shift and a process of undoing the slot ID.
[0168] For example, when remainder Re is 1, frame interpretation unit 203 shifts the payload segment to the left by 1 (S3108), as processing corresponding to step S3008, and decrements the slot ID by 1 (S3109), as processing corresponding to step S3009. Furthermore, when remainder Re is 2, frame interpretation unit 203 shifts the payload segment to the left by 2 (S3110), as processing corresponding to step S3010, and decrements the slot ID by 2 (S3111), as processing corresponding to step S3011. Furthermore, when remainder Re is L-1, frame interpretation unit 203 shifts the payload segment to the left by L-1 (S3112), as processing corresponding to step S3012, and decrements the slot ID by L-1 (S3113), as processing corresponding to step S3013.
[0169] As a result, the frame returns to the content generated in S3001, and the slot ID returns to the slot ID corresponding to the frame (for example, slot ID "1"). Therefore, frame interpretation unit 203 can properly obtain information (for example, speed) in the frame even if the frame has undergone bit shift calculation processing and slot ID change processing.
[0170] Next, the frame interpretation unit 203 reads and processes the data frame (S3103).
[0171] In this way, in this embodiment, the frame of the slot ID where an error was detected can be changed to a destination slot ID that is dynamically set according to the number of errors, so it is possible to prevent an attacker from predicting the destination and being attacked at the destination. For example, compared to when the destination slot ID is determined by a simple table, it is possible to prevent attacks at the destination.
[0172] (Modification of the third embodiment) The operation of the in-vehicle network system 10 according to this modification will be described with reference to Figs. 18 and 19. In this modification, a case will be described in which the slot ID to which the slot ID in which fraud was detected is changed dynamically changes based on time information (for example, transmission time) related to the frame in which fraud was detected. Fig. 18 is a diagram showing an example of the operation of the transmitting ECU according to the modification of the third embodiment. Note that the description of operations similar to the operation of the transmitting ECU according to the third embodiment will be omitted or simplified. Steps S4001 to S4003 are the same processes as steps S3001 to S3003 shown in Fig. 16, respectively. Furthermore, steps S4010 to S4016 are the same processes as steps S3007 to S3013 shown in Fig. 16, respectively.
[0173] As shown in FIG. 18, if the number of errors is not 0 (No in S4002), frame generation unit 205 calculates the elapsed time since the most recent error was detected (S4004). The elapsed time is, for example, the time from when the previous error was detected in the slot ID corresponding to the frame to when the current error is detected. For example, fraud determination unit 206 stores the time when the error was detected in switching table holding unit 208. Then, frame generation unit 205 may calculate the elapsed time based on that time.
[0174] Next, the frame generation unit 205 determines whether a predetermined time has elapsed (S4005). The frame generation unit 205 makes the above determination, for example, based on whether the elapsed time is equal to or greater than a predetermined time. The predetermined time is not particularly limited, but may be, for example, one hour.
[0175] If frame generation unit 205 determines that the predetermined time has elapsed (Yes in S4005), it changes the number of errors to 0 (S4006). That is, frame generation unit 205 resets the number of errors. Then, frame generation unit 205 executes the process of step S4003. That is, even if the number of errors is 1 or more, if the predetermined time has elapsed, frame generation unit 205 transmits the frame generated in step S4001 using the slot ID corresponding to that frame.
[0176] Furthermore, if the frame generation unit 205 determines that the predetermined time has not elapsed (No in S4005), it executes processing for performing at least one of a bit shift calculation process and a slot ID change process. This allows the frame generation unit 205 to execute processing for maintaining a safe state as the in-vehicle network system 10 when an error continues to occur (when an invalid state continues).
[0177] In this embodiment, frame generation unit 205 generates a pseudo-random number using the transmission time of the frame as a seed (S4007). The transmission time may be the scheduled time to transmit the frame, or the current time when processing to transmit the frame is being performed. Frame generation unit 205 then calculates a remainder Re of the pseudo-random number using the number of bits L of the payload segment (S4008), and executes different processes depending on the calculated remainder Re (S4009 to S4016).
[0178] Next, the frame generating unit 205 transmits a frame (for example, a frame subjected to bit shift operation processing) together with a transmission time at the transmission timing of the slot ID (empty slot ID) of the switching destination (S3003). The transmission time here is, for example, the same time as the transmission time used as the seed for generating the pseudo-random number in step S3007.
[0179] Although the transmission time is used as the seed in step S3007, this is not limiting. In step S3007, frame generation unit 205 may use, as the seed, information that allows synchronization between the transmitting and receiving ECUs. For example, frame generation unit 205 may generate a pseudo-random number using the number of cycles included in the frame generated in step S3001 as the seed, or may generate a pseudo-random number using the previous pseudo-random number as the seed. Note that the pseudo-random number may be generated using a method other than the above, and a similar process is performed in the receiving ECU. The similar process means that when the transmitting ECU generates a pseudo-random number using the previous pseudo-random number as the seed, the receiving ECU also generates a pseudo-random number using the previous pseudo-random number as the seed (see S4107 in FIG. 19, which will be described later). The two previous pseudo-random numbers have the same value.
[0180] Next, the operation of an ECU that receives a frame in the in-vehicle network system 10 according to this modification will be described with reference to Fig. 19. Fig. 19 is a diagram showing an example of the operation of the receiving ECU in the modification of the third embodiment. Note that the description of operations similar to the operation of the receiving ECU in the third embodiment will be omitted or simplified. Steps S4101 to S4103 are the same processes as steps S3101 to S3103 shown in Fig. 17, respectively. Furthermore, steps S4110 to S4116 are the same processes as steps S3107 to S3113 shown in Fig. 17, respectively.
[0181] 19, if the number of errors is not 0 (No in S4102), frame interpretation unit 203 calculates the elapsed time since the most recent error was detected from the transmission time included in the frame (S4104). For example, frame interpretation unit 203 stores the transmission time included in the frame in a storage unit (not shown). Frame interpretation unit 203 may then calculate the elapsed time based on the transmission time included in the received frame and the transmission time stored in the storage unit. The elapsed time calculated in S4104 is the same value as the elapsed time calculated in step S4004.
[0182] Next, the frame interpretation unit 203 determines whether a predetermined time has elapsed (S4105). The frame interpretation unit 203 makes this determination, for example, based on whether the elapsed time is equal to or greater than a predetermined time. Note that the predetermined time in step S4105 is the same as the predetermined time in step S4005, for example, one hour.
[0183] If the frame interpretation unit 203 determines that the predetermined time has elapsed (Yes in S4105), it changes the number of errors to 0 (S4106). In other words, the frame interpretation unit 203 resets the number of errors. Then, the frame interpretation unit 203 executes the process of S4103. In other words, even if the number of errors is 1 or more, if the predetermined time has not elapsed, the frame interpretation unit 203 reads and processes the data frame without processing the frame received in step S4101 (S4103).
[0184] Furthermore, if frame interpretation unit 203 determines that the predetermined time has not elapsed (No in S4105), it generates a pseudo-random number using the transmission time included in the frame as a seed (S4107). The pseudo-random number generated in S4107 has the same value as the pseudo-random number generated in step S4007. Then, frame interpretation unit 203 calculates a remainder Re of the pseudo-random number using the number of bits L of the payload segment (S4108). The remainder Re calculated in S4108 has the same value as the remainder Re calculated in step S4008. Then, frame interpretation unit 203 executes different processes depending on the calculated remainder Re (S4109 to S4116).
[0185] Thus, in this modification, the transmission time is an example of predetermined information for determining the slot ID of the switching destination.
[0186] Next, the frame interpretation unit 203 reads and processes the data frame (S4103).
[0187] In this way, in this embodiment, the frame of the slot ID in which an error was detected can be changed to a destination slot ID that is dynamically set according to time information, such as elapsed time, related to the frame in which the fraud was detected, thereby preventing an attacker from predicting the destination and being attacked at the destination. For example, compared to when the destination slot ID is determined by a simple table, this embodiment can prevent attacks at the destination.
[0188] (Fourth embodiment) [4-1. System Configuration] In this embodiment, a case will be described in which when the slot ID of a frame in which fraud is detected is switched, the slot ID of the switched-to slot changes dynamically. Specifically, a case will be described in which the slot ID of the switched-to slot of the slot ID in which fraud is detected changes dynamically based on the risk level of the frame in which an error occurs.
[0189] The risk level indicates the degree of impact on the safety of vehicle travel if fraudulent information (e.g., fraudulent payload information) is transmitted in the slot. The higher the risk level, the more accurate the payload information needs to be notified.
[0190] The risk level of a frame is set, for example, according to the type of signal included in the frame. The type of signal includes at least one of a "driving control signal" related to a control instruction for vehicle driving (e.g., driving, turning, stopping, etc.), a "body system control signal" related to a control instruction for the body system, and a "vehicle status signal" that notifies a status obtained from a sensor or the like (e.g., a status of the vehicle or its surroundings).
[0191] When setting the risk level for these types of signals, for example, if the signal included in the frame includes a driving control signal, the risk level is set to "high," if the signal included in the frame includes a body system control signal, the risk level is set to "medium," and if the signal included in the frame includes a vehicle status signal, the risk level is set to "low."
[0192] Alternatively, the risk level may be set based on the number of types of signals included in these frames. For example, a score may be assigned according to the type of signal, and the risk level may be set based on the sum of the scores of the types of signals included in the frame.
[0193] The risk level is not limited to three levels, "low," "medium," and "high," but may be two levels, or four or more levels. The risk level may also be expressed as a numerical value. For example, the risk level may be set as a numerical value between 0 (lowest risk level) and 100 (highest risk level).
[0194] The configuration of the in-vehicle network system according to this embodiment is the same as the in-vehicle network system 10 according to embodiment 1 or the in-vehicle network system 20 according to embodiment 2, and therefore a description thereof will be omitted. In the following, an example in which the configuration of the in-vehicle network system according to this embodiment is the same as the in-vehicle network system 10 according to embodiment 1 will be described.
[0195] First, the information stored in the in-vehicle network system 10 will be described with reference to Fig. 20. Fig. 20 is a diagram showing an example of a frame list transmitted by FlexRay communication in the fourth embodiment.
[0196] As shown in FIG. 20, a risk level is associated with each slot ID to which a frame is assigned. Specifically, a risk level is associated with a type of payload information. For example, in slot ID "1," the payload information is "speed," and the corresponding risk level is "low."
[0197] The slot ID "2" is a slot to which no frame is assigned. In other words, the slot ID "2" is an empty slot.
[0198] The switching table shown in the frame list of FIG. 20 is stored in the switching table storage unit 208, for example.
[0199] [4-2. System Operation] Next, the operation of the in-vehicle network system 10 according to this embodiment will be described with reference to Fig. 21A to Fig. 22. Fig. 21A is a diagram showing an example of the operation of the transmitting ECU in embodiment 4. Steps S5001 and S5002 shown in Fig. 21A are the same processes as steps S3001 and S3002 shown in Fig. 16, respectively.
[0200] 21A, when switching determination unit 207 determines that the number of errors is "0", that is, that no error has occurred (Yes in S5002), it notifies (outputs) information indicating that no error has occurred to frame generation unit 205. Frame generation unit 205 outputs a transmission frame request to frame transmission / reception unit 201 to transmit the generated frame. In accordance with the transmission frame request notified by frame generation unit 205, frame transmission / reception unit 201 transmits the frame at a transmission timing according to the slot ID of the frame (S5003).
[0201] Furthermore, if the switching determination unit 207 determines that the number of errors is not "0", that is, that an error has occurred (No in S5002), it refers to the contents of the frame list (for example, the frame list shown in FIG. 20) notified by the switching table holding unit 208, checks the risk level Ri of the detection target ID (slot ID in which an error was detected) (S5004), and outputs to the frame generation unit 205 a request to change the transmission content.
[0202] When frame generation section 205 receives information indicating that the transmission content is to be changed from switching determination section 207, frame generation section 205 executes different processes depending on the risk level Ri (S5005 to S5008).
[0203] If the risk level Ri is "low", frame generation unit 205 executes the process of step S5003. That is, even if the number of errors is 1 or more, if the risk level is a predetermined level or less (for example, the risk level is "low"), frame generation unit 205 transmits the frame generated in step S5001 using the slot ID corresponding to the frame.
[0204] Furthermore, if the risk level Ri is "medium", which is higher than "low", frame generation unit 205 shifts the payload segment to the right by 1 (S5005), and transmits the frame with the payload segment shifted to the right by 1 using the slot ID corresponding to that frame (S5003). Of the bit shift operation process and the slot ID change process, frame generation unit 205 executes only the bit shift operation process.
[0205] Furthermore, if the risk level Ri is "high", which is higher than "medium", frame generation unit 205 shifts the payload segment by 1 to the right (S5006), and transmits the frame with the payload segment shifted by 1 to the right using the slot ID corresponding to that frame (S5007). Then, frame generation unit 205 further changes the slot ID of that frame to a redundant slot ID (S5008). For example, an empty slot is assigned to the redundant slot. The redundant slot may be set in advance, or may be set dynamically depending on the risk level.
[0206] The frame generation unit 205 transmits a frame with the payload segment shifted by one to the right using a redundant slot ID (S5003). That is, when the risk level Ri is "high," the frame generation unit 205 transmits the same frame using different slot IDs. This allows the frame generation unit 205 to transmit the same frame multiple times (twice in the example of FIG. 21A). In this way, when the risk level Ri is equal to or higher than a predetermined level (for example, when the risk level Ri is "high"), for example, when a dangerous attack is detected, the frame generation unit 205 may perform processing to increase the transmission slot for the frame. In other words, when the risk level Ri is equal to or higher than a predetermined level, the frame generation unit 205 may transmit a redundant frame. A redundant frame is a frame transmitted using a redundant slot ID, and in FIG. 21A, it is a frame transmitted in step S5003 after step S5008. This prevents the processing to increase the transmission slot when the risk level is lower than a predetermined level, thereby reducing the processing load in the transmitting ECU.
[0207] Note that step S5006 does not have to be executed. That is, if the risk level is "high," frame generation unit 205 may perform processing to transmit the frame generated in step S5001 twice. Furthermore, frame generation unit 205 may change the amount of bit shift between steps S5005 and S5006.
[0208] Furthermore, frame generation unit 205 may execute the processing shown in Fig. 21B instead of the processing shown in Fig. 21A. Fig. 21B is a diagram showing another example of the operation of the transmitting ECU in embodiment 4. Note that in Fig. 21B, the same processes as those in Fig. 21A are denoted by the same reference numerals, and descriptions thereof will be omitted or simplified.
[0209] 21B, frame generation unit 205 may change the number of redundant slot IDs according to risk level Ri. For example, frame generation unit 205 may increase the number of redundant slot IDs in the frame as risk level Ri increases.
[0210] For example, if the risk level Ri is "medium," frame generation unit 205 transmits the frame generated in step S5001 using the slot ID corresponding to that frame (S5011), and changes the slot ID corresponding to that frame to one redundant slot ID (S5012). Then, frame generation unit 205 transmits the frame using one redundant slot ID (S5003). This allows frame generation unit 205 to transmit the same frame twice using different slot IDs.
[0211] Furthermore, for example, when the risk level Ri is "high," the frame generation unit 205 transmits the frame generated in step S5001 using the slot ID corresponding to the frame (S5013), and changes the slot ID corresponding to the frame to two redundant slot IDs (S5014). The frame generation unit 205 transmits the frame using each of the two redundant slot IDs (S5003). This allows the frame generation unit 205 to transmit the same frame three times using different slot IDs.
[0212] The number of redundant slot IDs changed in steps S5012 and S5014 is not limited to the above, and it is sufficient that the number of redundant slot IDs when the risk level Ri is "high" is greater than the number of redundant slot IDs when the risk level Ri is "medium." Furthermore, the redundant slot IDs changed in steps S5012 and S5014 may be different slot IDs, or at least one of them may be the same slot ID.
[0213] Thus, in this embodiment, the risk level of a frame is an example of predetermined information for determining the slot ID of the switching destination.
[0214] Note that the redundant slot ID in step S5008 of Fig. 21A and information related to the redundant slot ID in steps S5012 and S5014 shown in Fig. 21B may be included in the frame transmitted in step S5003, or may be transmitted in another free slot. This allows the transmitting and receiving ECUs to share information related to the redundant slot ID. The information related to the redundant slot ID includes, for example, information for identifying the redundant slot ID corresponding to slot ID "1."
[0215] Note that, in the above, an example has been described in which frame generation unit 205 acquires the risk level of a frame based on the frame list notified by switching table holding unit 208 in step S5004, but the present invention is not limited to this. Frame generation unit 205 may acquire the risk level of a frame generated in step S5001 by determining the risk level of the frame according to the type of signal included in the frame. For example, in step S5004, if the frame generated in step S5001 includes a "driving control signal," frame generation unit 205 may determine that the frame is "high."
[0216] Next, the operation of an ECU that receives a frame in the in-vehicle network system 10 according to this embodiment will be described with reference to Fig. 22. Fig. 22 is a diagram showing an example of the operation of the receiving ECU in the fourth embodiment. Note that steps S5101 to S5103 shown in Fig. 22 are the same processes as steps S3101 to S3103 shown in Fig. 17, respectively. Fig. 22 also shows the processing of the receiving ECU when the transmitting ECU has performed the processing shown in Fig. 21A.
[0217] As shown in FIG. 22 , if the number of errors is not 0 (No in S5102), the frame interpretation unit 203 determines whether the frame received in step S5101 is a redundant frame (S5104). The frame interpretation unit 203 may determine whether the frame received in step S5101 is a redundant frame, for example, based on information about the redundant slot ID acquired from the frame or a frame received at a different transmission timing from the frame (for example, an earlier transmission timing than the frame). Furthermore, when the frame interpretation unit 203 receives the frame transmitted in step S5007, for example, the frame interpretation unit 203 may execute processing to identify the redundant slot ID in the frame based on at least one of the number of errors and the risk level Ri in the frame. The frame interpretation unit 203 may execute processing in steps S5002, S5004, and S5008. This allows the receiving ECU to know which empty slot ID the transmitting ECU has set as the redundant slot ID. Then, based on the result of the determination, the frame interpretation unit 203 may determine whether or not the frame received in step S5101 is a redundant frame.
[0218] If the frame interpretation unit 203 determines that the frame is a redundant frame (Yes in S5104), it reads the stored frame (S5105). In this case, the stored frame means the frame transmitted in step S5007. The stored frame is stored in a memory unit (not shown).
[0219] Next, frame interpretation unit 203 determines whether the redundant frame matches the stored frame (S5106). The redundant frame and the stored frame should have the same content. For example, Data "0" to Data "n" included in the payload segment of the redundant frame and the stored frame should be the same. Therefore, frame interpretation unit 203 can determine whether either frame is an invalid frame based on whether the redundant frame matches the stored frame.
[0220] If the redundant frame matches the stored frame (Yes in S5106), the frame interpretation unit 203 executes processing to stop transmission of the redundant frame (S5107). The frame interpretation unit 203 outputs, for example, information indicating that information for stopping transmission of the redundant frame corresponding to the stored frame will be transmitted to the frame generation unit 205. The frame generation unit 205 transmits, for example, information for stopping transmission of the redundant frame corresponding to the stored frame using an empty slot ID.
[0221] Furthermore, if the redundant frame does not match the stored frame (No in S5106), the frame interpretation unit 203 adopts the average value of the two frames or the redundant frame (S5108). For information represented by a numerical value, such as speed, the frame interpretation unit 203 may, for example, use the average value of the two frames as the numerical value (e.g., speed) for that frame. This makes it possible to prevent the influence of an invalid frame from becoming too large, even if one of the frames is invalid. Furthermore, for information whose average value is meaningless, such as a flag value ("0" or "1"), the frame interpretation unit 203 preferentially adopts the information in the redundant frame. This allows the receiving ECU to adopt information from the redundant frame, which is less likely to be detected by an attacker, and therefore obtain more reliable information.
[0222] In the above description, the frame interpretation unit 203 adopts the average value of the two frames when the result of step S5106 is No, but the median, mode, or the like may be adopted.
[0223] If the result of step S5106 is No, the frame interpretation unit 203 may adopt the information of the redundant frame regardless of the type of information (for example, payload information) included in the frame.
[0224] Furthermore, when frame interpretation unit 203 determines that the frame is not a redundant frame (No in S5104), for example, when it determines that the frame was transmitted in step S5007 shown in FIG. 21A, it checks the risk level Ri of the detection target ID (slot ID of the frame) based on the frame list shown in FIG. 20 (S5109). Frame interpretation unit 203 checks the risk level Ri of the detection target ID (slot ID in which an error was detected) by referring to, for example, the contents of the frame list (for example, the frame list shown in FIG. 20). Then, frame interpretation unit 203 executes different processes depending on the risk level Ri (S5110 to S5112).
[0225] If the risk level Ri is "low", the frame interpretation unit 203 executes the process of step S5103.
[0226] Furthermore, if the risk level Ri is "medium", the frame generation unit 205 shifts the payload segment to the left by 1 (S5110) as processing corresponding to step S5005. Then, the frame interpretation unit 203 executes the processing of step S5103.
[0227] Furthermore, if the risk level Ri is "high," frame interpretation unit 203 shifts the payload segment to the left by 1 (S5111), as processing corresponding to step S5006. Then, frame interpretation unit 203 stores the frame with the payload segment shifted to the left by 1 in a storage unit (not shown) (S5112). The frame stored in step S5112 is used as the stored frame in step S5106. Then, frame interpretation unit 203 ends processing for the frame without executing data frame reading processing for the frame.
[0228] In this way, in this embodiment, the frame of the slot ID where an error was detected can be changed to a destination slot ID that is dynamically set according to the risk level of the frame, which prevents an attacker from predicting the destination and attacking the destination. For example, compared to when the destination slot ID is determined by a simple table, this prevents attacks even at the destination.
[0229] In the above, an example has been described in which different processes are executed depending on the risk level Ri of the detection target ID, but this is not limiting. The risk level Ri may also be determined based on the current vehicle state. The vehicle state may be parked, stopped, or moving, or the speed may be "slow," "medium," or "fast." For example, if the vehicle state includes speed, the risk level Ri is set higher as the speed increases. In this case, the vehicle information is an example of predetermined information for determining the slot ID to switch to.
[0230] Note that, in the above, an example has been described in which frame interpretation unit 203 acquires the risk level of the received frame based on the frame list in step S5109, but this is not limiting. Frame interpretation unit 203 may acquire the risk level of the frame by determining the risk level of the frame according to the type of signal included in the frame received in step S5101. For example, in step S5109, if the frame received in step S5101 includes a "driving control signal," frame interpretation unit 203 may determine that the risk level of the frame is "high."
[0231] (Modification of the fourth embodiment) The operation of the in-vehicle network system 10 according to this modification will be described with reference to Fig. 23. In this modification, an example will be described in which a receiving ECU detects whether a received frame is an unauthorized frame. Fig. 23 is a diagram showing an example of the operation of the receiving ECU according to the modification of the fourth embodiment.
[0232] 23, the frame transmitting / receiving unit 201 receives the frame transmitted in step S5003 (S6001). Step S6001 corresponds to step S5101 shown in FIG.
[0233] Next, the frame interpretation unit 203 corrects the bit position of the received frame (S6002). Step S6002 corresponds to step S5110 shown in FIG.
[0234] Next, the frame interpretation unit 203 reads and processes the data frame of the frame whose bit position has been corrected (S6003). Step S6003 corresponds to step S5103 shown in Fig. 22. The frame interpretation unit 203 outputs the read result to the fraud determination unit 206.
[0235] Next, the fraud determination unit 206 determines whether the decoded value based on the data frame is within a design value (S6004). The decoded value means numerical information extracted from the data frame. For example, if the payload information of the frame is speed, the decoded value is the speed extracted from the data frame. The design value is a value according to the type of payload information. If the payload information is speed, the design value is set to a value that is not realistically possible as a speed, and may be, for example, 3000 km / h.
[0236] Furthermore, if the frame has a field containing a magic number, the fraud determination unit 206 may perform the determination in step S6004 based on whether the value obtained by decoding the magic number matches a design value. In this case, the design value is set to a single numerical value rather than a range of values. Note that a decoded value that exactly matches the design value is an example of the decoded value being within the design value.
[0237] Furthermore, if the frame has a field containing a magic number, the fraud determination unit 206 may perform the determination in step S6004 based on whether the sequence of "0" and "1" (bit sequence) of the magic number matches a design value. In this case, the design value is a sequence of "0" and "1".
[0238] If the decoded value is within the design value (Yes in S6004), the fraud determination unit 206 ends the process of determining whether the frame received in step S6001 is an unauthorized frame. If the decoded value is not within the design value (No in S6004), the fraud determination unit 206 detects the frame as an unauthorized frame (S6005). The fraud determination unit 206 may output information indicating that the frame has been determined to be an unauthorized frame to the frame generation unit 205. Then, the frame generation unit 205 may transmit unauthorized frame information to another ECU, the unauthorized frame information including information for identifying the frame determined to be an unauthorized frame by the fraud determination unit 206 (for example, a slot ID) and information indicating that the frame is an unauthorized frame. The frame generation unit 205 may transmit the unauthorized frame information, for example, using an empty slot.
[0239] This means that, for example, if an attacker sends an unauthorized frame without knowing that it has been subjected to bit shift calculation processing, it is easy to determine whether the frame is unauthorized or not based on the sequence of ``0''s and ``1''s.
[0240] (Other variations) Although the present disclosure has been described based on the above-described embodiments, it goes without saying that the present disclosure is not limited to the above-described embodiments. The following cases are also included in the present disclosure.
[0241] (1) In the above embodiment 1, an example was shown in which the switching table is statically stored, but it may be created by dynamically searching for an available slot after communication starts. In this case, a new synchronization frame may be transmitted at the start of communication to share the tables with each other.
[0242] (2) In the above-mentioned first embodiment, an example was shown in which a transmission frame was switched from a slot before switching to a slot after switching, but it is also possible to continue transmitting both. In this case, the contents of the frames transmitted in both slots may be compared and adopted only if they are identical, or if there is a difference between the contents of the frames transmitted in both slots, only the contents of the frame transmitted in the slot after switching may be adopted.
[0243] (3) In the above embodiment, switching is performed by detecting a frame error, but the fraud detection method is not limited to this. It may be detected when a frame deviates from a predetermined payload, or fraud may be determined when a difference from the previous frame is large. Furthermore, the above-mentioned fraud detection results may be notified to the communication partner in a separate slot that is predetermined by both parties.
[0244] (4) In the above embodiment, an example was shown in which the ID to be switched is switched from a static slot to a dynamic slot, but it is also possible to switch from a dynamic slot to a static slot, or between dynamic slots, or between static slots.
[0245] (5) In the above embodiment, the switching is performed for each ID, but the payload position may be switched instead. The payload may be changed to an empty payload position, or may be switched with the existing payload position.
[0246] (6) In the above embodiment, the FlexRay protocol is used as the in-vehicle network, but this is not limiting. For example, CAN-FD (CAN with Flexible Data Rate), Ethernet, LIN (Local Interconnect Network), MOST (Media Oriented Systems Transport), etc. may also be used. Alternatively, a network may be formed by combining these networks as sub-networks.
[0247] (7) Each device in the above embodiments is specifically a computer system consisting of a microprocessor, ROM, RAM, hard disk unit, display unit, keyboard, mouse, etc. A computer program is recorded in the RAM or hard disk unit. Each device achieves its function when the microprocessor operates in accordance with the computer program. Here, a computer program is composed of a combination of multiple instruction codes that indicate commands to a computer to achieve a predetermined function.
[0248] (8) In each of the above embodiments, some or all of the constituent elements may be configured from a single system LSI (Large Scale Integration). A system LSI is an ultra-multifunctional LSI manufactured by integrating multiple components on a single chip, and specifically, is a computer system configured to include a microprocessor, ROM, RAM, etc. A computer program is recorded in the RAM. The system LSI achieves its functions when the microprocessor operates in accordance with the computer program.
[0249] Furthermore, each of the components constituting each of the above devices may be individually integrated into a single chip, or some or all of them may be integrated into a single chip.
[0250] The division of functional blocks in the block diagram is an example, and multiple functional blocks may be realized as a single functional block, one functional block may be divided into multiple blocks, or some functions may be moved to another functional block.Furthermore, the functions of multiple functional blocks having similar functions may be processed in parallel or in time-sharing by a single piece of hardware or software.
[0251] Although we refer to it as a system LSI here, it may also be called an IC, LSI, super LSI, or ultra LSI depending on the level of integration. Furthermore, the method of integration is not limited to LSI, but may be realized using dedicated circuits or general-purpose processors. It is also possible to use FPGAs (Field Programmable Gate Arrays), which can be programmed after LSI manufacturing, or reconfigurable processors, which allow the connections and settings of circuit cells within LSI to be reconfigured.
[0252] Furthermore, if an integrated circuit technology that can replace LSI emerges due to advances in semiconductor technology or other derivative technologies, it is natural that such technology may be used to integrate functional blocks. The application of biotechnology, etc. is also a possibility.
[0253] (9) Some or all of the components constituting each of the above devices may be configured as an IC card or a standalone module that can be attached to each device. The IC card or the module is a computer system composed of a microprocessor, ROM, RAM, etc. The IC card or the module may include the above-mentioned ultra-multifunctional LSI. The IC card or the module achieves its functions when the microprocessor operates according to a computer program. The IC card or the module may be tamper-resistant.
[0254] (10) The present disclosure may be embodied as the methods described above, a computer program for implementing these methods on a computer, or a digital signal comprising the computer program.
[0255] The present disclosure may also be a computer program or a digital signal recorded on a computer-readable recording medium, such as a flexible disk, a hard disk, a CD-ROM, an MO, a DVD, a DVD-ROM, a DVD-RAM, a BD (Blu-ray (registered trademark) Disc), a semiconductor memory, etc. Alternatively, the present disclosure may be the digital signal recorded on such a recording medium.
[0256] Furthermore, the present disclosure may involve transmitting the computer program or the digital signal via a telecommunications line, a wireless or wired communication line, a network such as the Internet, data broadcasting, or the like.
[0257] The present disclosure may also be a computer system having a microprocessor and a memory, the memory storing the computer program, and the microprocessor operating in accordance with the computer program.
[0258] The program or the digital signal may also be implemented by another independent computer system by recording it on the recording medium and transferring it, or by transferring it via the network or the like.
[0259] The order in which the steps in the flowchart are executed is merely an example for specifically explaining the present disclosure, and other orders may be used. Some of the steps may be executed simultaneously (in parallel) with other steps.
[0260] (11) The above-described embodiments and modifications may be combined with each other. [Industrial Applicability]
[0261] The present disclosure enables the in-vehicle network system as a whole to maintain a safe state. [Explanation of symbols]
[0262] 10, 20 In-vehicle network system 100a, 100b, 100c, 100d buses 200a, 200b, 200c, 200d, 1200a, 1200b, 1200c, 1200d ECU 201 Frame Transmitter / Receiver 202 Communication setting parameter storage unit 203, 1203 Frame interpretation section 204 External device control unit 205 Frame Generation Unit 206 Fraud Determination Department 207, 1207 Switching decision unit 208 Switching table holder 210 Front camera 220 gears 230 Brake 240 Rear Camera 300 Star Coupler 301a, 301b, 301c, 301d Transceiver section 302 Routing Department 1209 Vehicle condition determination unit L number of bits Remainder Ri Risk
Claims
1. A method for dealing with fraud in an in-vehicle network, comprising: Send and receive messages, Detecting fraudulent messages, If fraud is detected in the detection, switching the transmission timing of the message in which fraud is detected; In the switching, a transmission timing of the switching destination is changed in accordance with predetermined information, The predetermined information is (i) information indicating the number of times the fraud was detected and the time of sending the message in which the fraud was detected; (ii) the number of times the detection was made and the risk level of the message in which the fraud was detected; (iii) the number of times of detection in the detection and the vehicle state of the vehicle are included. How to deal with fraud.
2. A method for dealing with fraud in an in-vehicle network, comprising: Send and receive messages, Detecting fraudulent messages, If fraud is detected in the detection, switching the transmission timing of the message in which fraud is detected; In the switching, a transmission timing of the switching destination is changed in accordance with predetermined information, the predetermined information includes the number of times of detection in the detection; In the switching, a hash value of the number of detections is calculated, a remainder of the hash value is calculated by the number of bits of the payload segment of the message in which the fraud was detected, and a transmission timing according to the remainder is determined as the transmission timing of the switching destination. How to deal with fraud.
3. the predetermined information includes information indicating the number of times the fraud was detected and the time of transmission of the message in which the fraud was detected; In the switching, a pseudorandom number is generated using information indicating the transmission time as a seed, a remainder of the pseudorandom number is calculated by the number of bits of the payload segment of the message in which the fraud was detected, and a transmission timing according to the remainder is determined as the transmission timing of the switching destination. The fraud prevention method according to claim 1 .
4. The switching further includes performing a bit shift operation on the bit string that constitutes the payload segment by a bit shift amount corresponding to the remainder. The fraud prevention method according to claim 2 or 3.
5. The predetermined information includes the number of times the fraud was detected and the risk level of the message in which the fraud was detected, The switching is performed when the risk level is equal to or greater than a first threshold. The fraud prevention method according to claim 1 .
6. In the switching, if the risk level is equal to or greater than a first threshold, a bit shift operation is performed on a bit string constituting a payload segment of the message in which the fraud was detected, using a bit shift amount according to the risk level. The fraud prevention method according to claim 5.
7. In the switching, when the risk level is equal to or higher than a second threshold lower than the first threshold and is lower than the first threshold, a bit shift operation process is performed on a bit string constituting the payload segment by a bit shift amount according to the risk level. The fraud prevention method according to claim 6.
8. In the switching, when the degree of risk is equal to or greater than a third threshold higher than the first threshold, a plurality of transmission timings according to the degree of risk are determined as the transmission timing to be switched to. The fraud handling method according to any one of claims 5 to 7.
9. The switching is performed when the number of detections is equal to or greater than a predetermined number. The fraud handling method according to any one of claims 1 to 8.
10. The switch is performed when the time elapsed since the last fraud detection is less than or equal to a predetermined time. The fraud handling method according to any one of claims 1 to 8.
11. In the switching, after the message is transmitted at the transmission timing of the message in which the fraud is detected, the transmission timing of the message is switched. The fraud handling method according to any one of claims 1 to 10.
12. a communication method in the in-vehicle network is a time-triggered communication method based on a time slot; The transmission and reception of the message is performed within a predetermined time slot; In the switching, a slot of the switching destination is determined as the transmission timing of the switching destination. The fraud handling method according to any one of claims 1 to 11.
13. the time slots include a plurality of free slots to which no messages are assigned; In the switching, an empty slot according to the predetermined information is determined as a slot to be switched to. The fraud prevention method according to claim 12.
14. A synchronization message is sent to notify the determined destination slot. The fraud prevention method according to claim 13.
15. In the switching, after determining the slot to which the switching is to be performed, a message is generated by combining the payload of the message assigned to the slot before the switching and the payload of the message assigned to the slot after the switching; In the message transmission / reception, the generated message is transmitted. The fraud prevention method according to claim 12.
16. In the switching, a new slot is determined as the slot to be switched to. The fraud prevention method according to claim 12.
17. In the switching, the payload of the message assigned to the slot before the switching is exchanged with the payload of the message assigned to the slot after the switching. The fraud prevention method according to claim 12.
18. A fraud prevention device in an in-vehicle network, a message sending / receiving unit for sending and receiving messages; a fraud detection unit that detects fraudulent messages; a switching processing unit that switches a transmission timing of the message in which fraud is detected when fraud is detected by the fraud detection unit, the switching processing unit changes the transmission timing of the switching destination in accordance with predetermined information; The predetermined information is (i) information indicating the number of times the fraud detection unit detected the fraud and the time of transmission of the message in which the fraud was detected; (ii) the number of times the detection was made and the risk level of the message in which the fraud was detected; (iii) the number of times of detection in the detection and the vehicle state of the vehicle are included. Fraud prevention device.
19. A fraud prevention device in an in-vehicle network, a message sending / receiving unit for sending and receiving messages; a fraud detection unit that detects fraudulent messages; a switching processing unit that switches a transmission timing of the message in which fraud is detected when fraud is detected by the fraud detection unit, the switching processing unit changes the transmission timing of the switching destination in accordance with predetermined information; the predetermined information includes the number of times of detection in the detection; The switching processing unit calculates a hash value of the number of detections, calculates a remainder of the hash value by the number of bits of a payload segment of the message in which the fraud was detected, and determines a transmission timing according to the remainder as the transmission timing of the switching destination. Fraud prevention device.
20. A program for causing a computer to execute the fraud prevention method according to any one of claims 1 to 17.
Citation Information
Patent Citations
Production of extract of sweet potato
JP1981064799A
Channel quality managing method / device
JP1998247887A
Bus Guardian with improved channel monitoring
JP2009516410A
Wireless communication method
JP2012244563A